Information
Room
- Name: Bolt
- Profile: tryhackme.com
- Difficulty: Easy
- Description: A hero is unleashed
Write-up
Overview
Install tools used in this WU on BlackArch Linux:
Network enumeration
Port and service scan with nmap:
Let's add a domain for this IP:
Web discovery
The app at http://bolt.htm:8000/ is built using Bolt CMS.
We can find some credentials in the posts, Jake (Admin) username is bolt and
password is boltadmin123.
We can log in at http://bolt.htm:8000/bolt/login and see the version displayed
at the bottom of the page.
Web exploitation
With luck, we'll be able to use the authenticated RCE:
We can set up metapsloit then:
I didn't expect that be it seems we're directly root: